HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 259

HW Terminal Access Controller Access Control, AAA MPLS L3VPN implementation

Page 259 highlights

fixed ARP configuration, 181 format 802.1X EAP packet format, 61 802.1X EAPOL packet format, 61 802.1X packet, 61 AAA HWTACACS username, 34 AAA RADIUS username, 25 MAC authentication user account, 80 RADIUS packet format, 4 forwarding ARP restricted forwarding, 179 IP source guard configuration, 161, 162 IPv4 source guard dynamic configuration with DHCP relay, 169 IPv4 source guard dynamic configuration with DHCP snooping, 167 IPv4 source guard static configuration, 165 IPv6 source guard static configuration, 170 FTP local host public key distribution, 117 SFTP client device configuration, 135 SFTP client publickey authentication configuration, 155 SFTP client source IP address or interface specification, 135 SFTP configuration, 153 SFTP directories, 137 SFTP files, 137 SFTP server connection establishment, 135 SFTP server connection termination, 138 SFTP server password authentication configuration, 153 G gateway protection configuration (ARP), 182, 183 generating security SSH local DSA key pair, 127 security SSH local RSA key pair, 127 H handshake function (802.1X online user), 72 history (password control), 107 HP RADIUS HP proprietary attributes, 15 HW Terminal Access Controller Access Control System. Use HWTACACS HWTACACS AAA configuration, 1, 17 AAA for SSH user, 45 AAA implementation, 7 AAA MPLS L3VPN implementation, 13 AAA scheme configuration, 18 accounting server specification, 32 authentication server specification, 31 authorization server specification, 32 differences between HWTACACS and RADIUS, 7 displaying, 36 maintaining, 36 outgoing packet source IP address, 34 packet exchange process, 7 real-time accounting timer (realtime-accounting), 35 scheme configuration, 30 scheme creation, 31 scheme VPN specification, 33 server quiet timer (quiet), 35 server response timeout timer (response-timeout), 35 shared keys specification, 33 SSH user local authentication+HWTACACS authorization+RADIUS accounting, 46 traffic statistics units, 34 troubleshooting, 57 username format, 34 I ignoring port security server authorization information, 95 IKE aggressive mode in phase 1, 222 configuring global ID, 229 configuring IKE DPD, 230 configuring IKE keepalive, 229 configuring IKE keychain, 228 configuring IKE NAT keepalive, 230 configuring IKE-based IPsec policy, 207 configuring number limit for IKE SAs, 231 DH algorithm, 223 DH group, 227 displaying, 232 DPD, 225 enabling invalid SPI recovery, 231 250

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

250
fixed ARP configuration,
181
format
802.1X EAP packet format,
61
802.1X EAPOL packet format,
61
802.1X packet,
61
AAA HWTACACS username,
34
AAA RADIUS username,
25
MAC authentication user account,
80
RADIUS packet format,
4
forwarding
ARP restricted forwarding,
179
IP source guard configuration,
161
,
162
IPv4 source guard dynamic configuration with
DHCP relay,
169
IPv4 source guard dynamic configuration with
DHCP snooping,
167
IPv4 source guard static configuration,
165
IPv6 source guard static configuration,
170
FTP
local host public key distribution,
117
SFTP client device configuration,
135
SFTP client publickey authentication
configuration,
155
SFTP client source IP address or interface
specification,
135
SFTP configuration,
153
SFTP directories,
137
SFTP files,
137
SFTP server connection establishment,
135
SFTP server connection termination,
138
SFTP server password authentication
configuration,
153
G
gateway protection configuration (ARP),
182
,
183
generating
security SSH local DSA key pair,
127
security SSH local RSA key pair,
127
H
handshake function (802.1X online user),
72
history (password control),
107
HP
RADIUS HP proprietary attributes,
15
HW Terminal Access Controller Access Control
System.
Use
HWTACACS
HWTACACS
AAA configuration,
1
,
17
AAA for SSH user,
45
AAA implementation,
7
AAA MPLS L3VPN implementation,
13
AAA scheme configuration,
18
accounting server specification,
32
authentication server specification,
31
authorization server specification,
32
differences between HWTACACS and RADIUS,
7
displaying,
36
maintaining,
36
outgoing packet source IP address,
34
packet exchange process,
7
real-time accounting timer
(realtime-accounting),
35
scheme configuration,
30
scheme creation,
31
scheme VPN specification,
33
server quiet timer (quiet),
35
server response timeout timer
(response-timeout),
35
shared keys specification,
33
SSH user local authentication+HWTACACS
authorization+RADIUS accounting,
46
traffic statistics units,
34
troubleshooting,
57
username format,
34
I
ignoring
port security server authorization information,
95
IKE
aggressive mode in phase 1,
222
configuring global ID,
229
configuring IKE DPD,
230
configuring IKE keepalive,
229
configuring IKE keychain,
228
configuring IKE NAT keepalive,
230
configuring IKE-based IPsec policy,
207
configuring number limit for IKE SAs,
231
DH algorithm,
223
DH group,
227
displaying,
232
DPD,
225
enabling invalid SPI recovery,
231